Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC22
Muhammad-Ali007/OutlookNTLM_CVE-2023-23397
CVE-2023-23397CRITICALbajo ataque14 jul 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Pog-Frog/cve-2022-44268
CVE-2022-44268MEDIUM14 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC1
CVE-2023-33592批量漏洞利用程序
CVE-2023-3359214 jul 2023
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RIESGO
abrir
GitHub PoC1
Recent Campaign abusing CVE-2023-36884
CVE-2023-36884HIGHbajo ataqueransomware13 jul 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC
Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability
CVE-2002-074813 jul 2023
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET reques
28RIESGO
abrir
GitHub PoC106
Full Chain Analysis of CVE-2022-4262, a non-trivial feedback slot type confusion in V8.
CVE-2022-4262HIGHbajo ataque13 jul 2023
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corru
76RIESGO
abrir
GitHub PoC2
This is a Python3 script that demonstrates an exploit for a Blind SQL Injection vulnerability in WebERP version 4.15.
CVE-2019-1329213 jul 2023
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is d
23RIESGO
abrir
GitHub PoC26
The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection script checks if they exist. Provided AS-IS without any warrenty.
CVE-2023-36884HIGHbajo ataqueransomware12 jul 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC
F5-BIG-IP Remote Code Execution Vulnerability CVE-2022-1388: A Case Study
CVE-2022-1388CRITICALbajo ataqueransomware12 jul 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC13
This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server. The script supports both Windows and Linux (On testing) platforms, and it can be used to exploit individual targets or perform mass checking on a list of URLs.
CVE-2023-24489CRITICALbajo ataque12 jul 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RIESGO
abrir
GitHub PoC1
asepsaepdin/CVE-2021-1732
CVE-2021-1732HIGHbajo ataqueransomware11 jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
Python script that generates pfs payloads to exploit CVE-2022-4510
CVE-2022-4510HIGH11 jul 2023
Path Traversal in binwalk
46RIESGO
abrir
GitHub PoC2
Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)
CVE-2023-27997CRITICALbajo ataqueransomware11 jul 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC2
CVE-2023-27372-SPIP-CMS-Bypass
CVE-2023-27372CRITICAL11 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC7
Exploit and scanner for CVE-2023-3460
CVE-2023-346011 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
GitHub PoC
CVE-2023-3460
CVE-2023-346011 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
GitHub PoC
asepsaepdin/CVE-2021-3560
CVE-2021-3560HIGHbajo ataque10 jul 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
asepsaepdin/CVE-2021-4034
CVE-2021-4034HIGHbajo ataque10 jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC6
asepsaepdin/CVE-2023-22809
CVE-2023-22809HIGH10 jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC
bthnrml/guncel-cve-2019-9053.py
CVE-2019-905309 jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC4
A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.
CVE-2023-32235HIGH09 jul 2023
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RIESGO
abrir
GitHub PoC1
Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.
CVE-2022-0847HIGHbajo ataque09 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
Mass CVE-2023-3460.
CVE-2023-346009 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
GitHub PoC10
POC for CVE-2023-34362 affecting MOVEit Transfer
CVE-2023-34362CRITICALbajo ataqueransomware09 jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
GitHub PoC
Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH08 jul 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RIESGO
abrir
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code and gain privileges via the SchedulerService.exe component.
CVE-2023-3616508 jul 2023
20RIESGO
abrir
GitHub PoC2
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL
CVE-2023-3616308 jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RIESGO
abrir
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code via the MTAgentService component
CVE-2023-3616408 jul 2023
20RIESGO
abrir
GitHub PoC
Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.
CVE-2015-157807 jul 2023
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir
GitHub PoC
rizqimaulanaa/CVE-2023-3460
CVE-2023-346007 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
anteriorpágina 266 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.